What’s mandatory in September is CAA checking on the CA side, but as @tialaramex explains, “no CAA records” is a valid reply which will not prevent certificate issuance.
schoen
3
Related topics
| Topic | Replies | Views | Activity | |
|---|---|---|---|---|
| Cant renew cert: DNS problem: SERVFAIL looking up CAA | 20 | 6377 | October 6, 2017 | |
| Why letsencrypt query my DNS for CAA record? | 4 | 3455 | May 15, 2016 | |
| How to use without CAA? | 16 | 6886 | August 20, 2017 | |
| Is there any way to pass validation if DNS Server does not respond to CAA? | 9 | 2963 | February 15, 2017 | |
| Let's encrypt returns "query timed out looking up CAA for <domain_name>" error when obtaining a new certificate | 12 | 12546 | January 6, 2018 |